Back
Idff1bec81-e241-44bf-98ed-c6e37805a2e3
RulenamePROD (TM018.1) - DOMAIN - Child Domain promoted within the Forest
DescriptionNew child domain has been promoted within the Forest and should have the Tier Model deployed.
SeverityHigh
TacticsPrivilegeEscalation
TechniquesT1484.002
Required data connectorsSecurityEvents
WindowsSecurityEvents
KindScheduled
Query frequency1h
Query period1h
Trigger threshold0
Trigger operatorgt
Source Urihttps://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Active%20Directory%20Tier%20Model/Analytic%20Rules/TM018_DOMAINChildDomainPromotedWithinTheForest.yaml
Version1.0.0
Arm templateff1bec81-e241-44bf-98ed-c6e37805a2e3.json
Deploy To Azure
SecurityEvent 
| where EventID == 5137 and EventData has '"ObjectClass">crossRef' and EventData has 'CN=Partitions,CN=Configuration'
| extend ObjectName = extract("(?i)CN=([^,]+),(?i)CN=Partitions,(?i)CN=Configuration", 1, EventData)
| extend ActivityType = extract("([a-zA-Z]+)\\.$", 1, Activity)
| extend Domain = extract("([^.]+\\.[^.]+)$", 1, Computer)
| project TimeGenerated
        , ObjectName
        , ActivityType
        , Account
        , Domain
        , Computer
        , Channel
        , EventID
        , EventData
incidentConfiguration:
  groupingConfiguration:
    lookbackDuration: PT5H
    reopenClosedIncident: false
    matchingMethod: AllEntities
    enabled: false
  createIncident: true
name: PROD (TM018.1) - DOMAIN - Child Domain promoted within the Forest
triggerOperator: gt
query: |
  SecurityEvent 
  | where EventID == 5137 and EventData has '"ObjectClass">crossRef' and EventData has 'CN=Partitions,CN=Configuration'
  | extend ObjectName = extract("(?i)CN=([^,]+),(?i)CN=Partitions,(?i)CN=Configuration", 1, EventData)
  | extend ActivityType = extract("([a-zA-Z]+)\\.$", 1, Activity)
  | extend Domain = extract("([^.]+\\.[^.]+)$", 1, Computer)
  | project TimeGenerated
          , ObjectName
          , ActivityType
          , Account
          , Domain
          , Computer
          , Channel
          , EventID
          , EventData
queryFrequency: 1h
description: |
  New child domain has been promoted within the Forest and should have the Tier Model deployed.
id: ff1bec81-e241-44bf-98ed-c6e37805a2e3
triggerThreshold: 0
queryPeriod: 1h
version: 1.0.0
kind: Scheduled
customDetails:
  ObjectName: ObjectName
  Domain: Domain
  ActivityType: ActivityType
  Account: Account
  EventData: EventData
  EventID: EventID
  Channel: Channel
  Computer: Computer
status: Available
eventGroupingSettings:
  aggregationKind: AlertPerResult
severity: High
requiredDataConnectors:
- connectorId: SecurityEvents
  dataTypes:
  - SecurityEvent
- connectorId: WindowsSecurityEvents
  dataTypes:
  - SecurityEvent
OriginalUri: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Active%20Directory%20Tier%20Model/Analytic%20Rules/TM018_DOMAINChildDomainPromotedWithinTheForest.yaml
alertDetailsOverride:
  alertDescriptionFormat: New child domains do not have a Tier Model by default. Deploy and configure the Tier Model within the new child domain.
  alertDisplayNameFormat: (TM018.1) A new Child Domain has been promoted and requires the Tier Model to be deployed
relevantTechniques:
- T1484.002
tactics:
- PrivilegeEscalation
entityMappings:
- fieldMappings:
  - identifier: FullName
    columnName: ObjectName
  entityType: Account
- fieldMappings:
  - identifier: HostName
    columnName: Computer
  entityType: Host
- fieldMappings:
  - identifier: FullName
    columnName: Account
  entityType: Account
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "workspace": {
      "type": "String"
    }
  },
  "resources": [
    {
      "apiVersion": "2024-01-01-preview",
      "id": "[concat(resourceId('Microsoft.OperationalInsights/workspaces/providers', parameters('workspace'), 'Microsoft.SecurityInsights'),'/alertRules/ff1bec81-e241-44bf-98ed-c6e37805a2e3')]",
      "kind": "Scheduled",
      "name": "[concat(parameters('workspace'),'/Microsoft.SecurityInsights/ff1bec81-e241-44bf-98ed-c6e37805a2e3')]",
      "properties": {
        "alertDetailsOverride": {
          "alertDescriptionFormat": "New child domains do not have a Tier Model by default. Deploy and configure the Tier Model within the new child domain.",
          "alertDisplayNameFormat": "(TM018.1) A new Child Domain has been promoted and requires the Tier Model to be deployed"
        },
        "alertRuleTemplateName": "ff1bec81-e241-44bf-98ed-c6e37805a2e3",
        "customDetails": {
          "Account": "Account",
          "ActivityType": "ActivityType",
          "Channel": "Channel",
          "Computer": "Computer",
          "Domain": "Domain",
          "EventData": "EventData",
          "EventID": "EventID",
          "ObjectName": "ObjectName"
        },
        "description": "New child domain has been promoted within the Forest and should have the Tier Model deployed.\n",
        "displayName": "PROD (TM018.1) - DOMAIN - Child Domain promoted within the Forest",
        "enabled": true,
        "entityMappings": [
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "ObjectName",
                "identifier": "FullName"
              }
            ]
          },
          {
            "entityType": "Host",
            "fieldMappings": [
              {
                "columnName": "Computer",
                "identifier": "HostName"
              }
            ]
          },
          {
            "entityType": "Account",
            "fieldMappings": [
              {
                "columnName": "Account",
                "identifier": "FullName"
              }
            ]
          }
        ],
        "eventGroupingSettings": {
          "aggregationKind": "AlertPerResult"
        },
        "incidentConfiguration": {
          "createIncident": true,
          "groupingConfiguration": {
            "enabled": false,
            "lookbackDuration": "PT5H",
            "matchingMethod": "AllEntities",
            "reopenClosedIncident": false
          }
        },
        "OriginalUri": "https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Microsoft%20Active%20Directory%20Tier%20Model/Analytic%20Rules/TM018_DOMAINChildDomainPromotedWithinTheForest.yaml",
        "query": "SecurityEvent \n| where EventID == 5137 and EventData has '\"ObjectClass\">crossRef' and EventData has 'CN=Partitions,CN=Configuration'\n| extend ObjectName = extract(\"(?i)CN=([^,]+),(?i)CN=Partitions,(?i)CN=Configuration\", 1, EventData)\n| extend ActivityType = extract(\"([a-zA-Z]+)\\\\.$\", 1, Activity)\n| extend Domain = extract(\"([^.]+\\\\.[^.]+)$\", 1, Computer)\n| project TimeGenerated\n        , ObjectName\n        , ActivityType\n        , Account\n        , Domain\n        , Computer\n        , Channel\n        , EventID\n        , EventData\n",
        "queryFrequency": "PT1H",
        "queryPeriod": "PT1H",
        "severity": "High",
        "status": "Available",
        "subTechniques": [
          "T1484.002"
        ],
        "suppressionDuration": "PT1H",
        "suppressionEnabled": false,
        "tactics": [
          "PrivilegeEscalation"
        ],
        "techniques": [
          "T1484"
        ],
        "templateVersion": "1.0.0",
        "triggerOperator": "GreaterThan",
        "triggerThreshold": 0
      },
      "type": "Microsoft.OperationalInsights/workspaces/providers/alertRules"
    }
  ]
}